ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Beware insider threats: the number one cause of data breaches

Insider threats account for 60% of data breaches and cost businesses an average of $15.4 million per year. Now is the time to pay attention, argues Samantha Humphries at Exabeam

 

September is Insider Threat Awareness Month, which aims to educate individuals and organisations on the dangers of insider threats and how to stop them, no matter what form they take. These threats, posed by legitimate users, can prove more elusive and harder to detect than traditional external threats.

 

One of the biggest challenges when protecting against insider threats is their unpredictable and quiet nature. When it comes to external threats, with someone trying to breach a well protected endpoint for example, there will be numerous alarms and alerts triggered by security systems.

 

However, these same security systems rarely turn their attention inward, so businesses could be haemorrhaging data via insider threats for any amount of time without even knowing.

 

Let’s begin by exploring the most common categories of insider risk:

  • Disgruntled employees. These people set out to intentionally steal corporate data – either for personal profit or as a method of revenge. Because of their legitimate credentials and permitted access to sensitive data, it is possible for rogue employees to remain undetected for longer than traditional threats.
  • Third-party contractors. Not necessarily full, salaried employees, but contractors or freelancers with similar levels of access to sensitive data. They may work onsite and have detailed knowledge of internal processes.
  • Careless employees. Not every internal threat is malicious, there are plenty that arise out of carelessness or ignorance. When employees click on phishing links in emails, leave their security credentials lying around, or access the corporate network via unsecured public WiFi, it can provide the perfect back door to hackers and criminals. 
  • Compromised credentials. The result of careless employees is that credentials can become compromised without anyone necessarily knowing. This means cybercriminals can evade security protocols by appearing as a legitimate actor. This can make them hard to detect and the longer they go undetected, the more damage they can do.

Creating an effective defence

Regardless of the size of your business, these threats are real, however, there is a range of tools and technologies on the market that can help in the battle against them, from training through to behavioural analytics.

 

Train your employees from day one

Perhaps the simplest, but also a very effective method: train each employee to mitigate risky behaviour and prevent them from becoming unintentional threats. By educating your workforce about the dangers of phishing attacks and social engineering, they will become a frontline defence against the most common types of threats.

 

Moreover, training your employees about rogue elements means they can help spot suspicious behaviour among colleagues.

 

Put behavioural analytics at the heart of your defence

User and Entity Behaviour Analytics (UEBA) is one of the most powerful technologies at our disposal. It first creates a baseline of regular activity – using machine learning – for all systems, employees, and third parties.

 

For example, office workers typically are operational between 9am and 6pm and spend 90% of their time using Office applications. Once these baselines have been built, deviations can be picked up instantly and automatically flagged as potential security alerts.

 

So, if an employee in marketing is trying to access sensitive financial data or applications at 2am, your UEBA solution will flag it, enabling your security team to take further action immediately. This goes beyond just automated data collection into a much smarter, observational approach to behavioural analysis.

 

These alerts, combined with contextual information, ensure you can highlight insider threats much more quickly than using traditional, time-consuming manual analysis and investigation, making it an efficient way of identifying insider threat attacks before major damage is done.

 

As the battle against malicious behaviour continues to be waged, internal threats will remain at the forefront as one of the most powerful enemies that businesses face.

 

By taking the lead on simple steps, such as security training, and introducing sophisticated new technological tools, such as UEBA, we can detect threats before they do too much damage, thus keeping data secure and protecting businesses’ reputations.

 


 

Samantha Humphries is Head of Security Strategy EMEA at Exabeam.

 

Main image courtesy of iStockPhoto.com

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543